Splunk Search

How to overlay daily avg on count per day using timechart?

Motivator

I have the basic search of for count by day

index=foo
| bin _time span=1d 
| timechart count

How can I overlay the daily avg of count per day?

Thx

0 Karma

Ultra Champion
| tstats count where index=foo prestats=t by _time span=1d
| timechart count
| eventstats avg(count) as daily_avg

Visualization with overlay daily_avg
How about this?

Builder

Can you please elaborate, or possibly provide some examples? The count per day is just that: a single value. What are you trying to average? The timechart command itself allows bucketing by day with the span=1d option, and can perform statistical aggregations including avg and count.

0 Karma